mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete (CVE-2026-50027) | HOL Guard CVE